Closed
Description
Description
Users can associate observables with cases for better tracking and analysis in incident response workflows. This improves investigative efficiency by correlating observables across multiple cases.
Misc. notes:
- The max number of observables that users can create (via the Add observable modal) is 50.
- The max number of observable types is 10.
- This feature is GA'd in Serverless and will be released in 8.18/9.0.0 for ESS.
- The Similar cases tab allows users to find other cases with the same observables (identical type and value).
- Observable types can be managed from the Case settings page.
- Only observables that belong to a non-deleted type are visible.
Background & resources
- PRs: [Security Solution] [Cases] Introduce case observables (phase 0 & 1) kibana#190237
- Issues/metas:
- Point of contact: @lgestc
- Test environments: Use Serverless QA project
Which documentation set does this change impact?
ESS and serverless
ESS updates are below. The Serverless updates will be the same.
Changes to the Configure case settings page:
- Update intro para
- Refresh the following page images:
- cases-settings.png - Autogenerated, don't update
- cases-add-template.png - Autogenerated, don't update
- Add a new section to the Configure case settings page titled “Observable types”. This should go after the “Templates” section.
Changes to the Open and manage cases page:
- Create a new section titled “Create and manage observables”
- Refresh the following images:
- Cases-ui-open.png - Autogenerated, don't update
- cases-summary.png
- cases-alert-tab.png
- cases-files.png - Autogenerated, don't update
- add-vis-to-case.gif
In the Manage existing cases section:
- Add to the list of things users can do with cases. Link to the new “Create and manage observables” section.
ESS release
8.18 and 9.0
Serverless release
January 7, 2025
Feature differences
N/A
API docs impact
N/A
Prerequisites, privileges, feature flags
ESS license - TBD
Serverless feature tier - Essentials
Metadata
Metadata
Assignees
Labels
Issues that apply to docs in the Stack releaseIssues for Serverless SecurityIssues that take moderate but not substantial time to completeCases issuesIssues that are time-sensitive and/or are of high customer importanceFormerly Data VisibilityAn issue that's currently blocked because it’s pending info or action from stakeholders.